PYPI · SEPTEMBER 2026 · EARLY WARNING

Omnigent Package Vulnerability: Authenticated RCE Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
omnigent (pypi)
Affected versions
< 0.3.0 or >= 0.0.1rc1, <= 0.0.1rc1 or >= 0.0.1rc2, <= 0.0.1rc2 or >= 0.1.0, <= 0.1.0 or >= 0.1.0rc1, <= 0.1.0rc1 or >= 0.1.0rc2, <= 0.1.0rc2 or >= 0.1.0rc3, <= 0.1.0rc3 or >= 0.1.0rc4, <= 0.1.0rc4 or >= 0.1.1, <= 0.1.1 or >= 0.1.1rc2, <= 0.1.1rc2 or >= 0.2.0, <= 0.2.0 or >= 0.2.0rc1, <= 0.2.0rc1 or >= 0.3.0rc1, <= 0.3.0rc1 or < 0.3.0 or >= 0.0.1rc1, <= 0.0.1rc1 or >= 0.0.1rc2, <= 0.0.1rc2 or >= 0.1.0, <= 0.1.0 or >= 0.1.0rc1, <= 0.1.0rc1 or >= 0.1.0rc2, <= 0.1.0rc2 or >= 0.1.0rc3, <= 0.1.0rc3 or >= 0.1.0rc4, <= 0.1.0rc4 or >= 0.1.1, <= 0.1.1 or >= 0.1.1rc2, <= 0.1.1rc2 or >= 0.2.0, <= 0.2.0 or >= 0.2.0rc1, <= 0.2.0rc1 or >= 0.3.0rc1, <= 0.3.0rc1
Patched version
Not yet available
GHSA-JRRM-9HC7-2V3H

An early warning has been issued for a high-severity vulnerability in the omnigent package. An authenticated user with edit access to their own session can reportedly overwrite a shared/template agent, leading to remote code execution.

What happened

The vulnerability, tracked as GHSA-JRRM-9HC7-2V3H, allows an authenticated user with edit access to overwrite a shared/template agent by uploading a full agent bundle. This can lead to remote code execution. The issue has been reported but is not yet confirmed. The vulnerability affects versions of the omnigent package less than 0.3.0 or within certain release candidate ranges as specified in the threat data.

The vulnerability was first flagged on September 2, 2026. It is currently under investigation and has not been reported as exploited in the wild. Users are advised to take precautionary measures to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If omnigent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using a version of the omnigent package less than 0.3.0 or within the specified release candidate ranges.

What should I do right now?

Upgrade to the latest version of the omnigent package and review session permissions to prevent unauthorized agent uploads.

Has an official fix been released?

No official fix has been published yet. Monitor the sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats